Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1172 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.17% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.10.0, the use of the `assert` function to handle errors frequently causes the module to crash. This is particularly critical because the manager shuts down all other modules and exits when any one of them terminates, leading to a denial of service. In a… | |
| Analizada | Baja (2.4) | 0.28% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermeter SLIP parser reads `vec[vec.size()-1]` and `vec[vec.size()-2]` without checking that at least two bytes are present. Malformed SLIP frames on the serial link can reach `is_message_crc_correct` with… | |
| Analizada | Alta (7.4) | 0.39% | — | Linuxfoundation Everest | 21/1/2026 | 17/6/2026 | EVerest is an EV charging software stack. In versions 2025.9.0 and below, an attacker can exhaust the operating system's memory and cause the module to terminate by initiating an unlimited number of TCP connections that never proceed to ISO 15118-2 communication. This is possible because a new thread is started for… | |
| Analizada | Alta (7.5) | 0.46% | — | Liquidweb Restrict Content | 16/1/2026 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 3.2.16 via the 'rcp_stripe_create_setup_intent_for_saved_card' function due to missing capability check. Additionally, the plugin does not check a user-controlled key, which makes… | |
| Modificada | Alta (7.1) | 0.22% | — | Themegoods Grand Restaurant | 8/1/2026 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Grand Restaurant grandrestaurant allows Reflected XSS.This issue affects Grand Restaurant: from n/a through < 7.0.9. | |
| Aplazada | Media (6.4) | 0.33% | — | Snillrik RestaurantAI | 7/1/2026 | 17/6/2026 | The Snillrik Restaurant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'menu_style' shortcode attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Aplazada | Media (4.3) | 0.40% | 💥 PoC | ACF TO Rest APIAI | 7/1/2026 | 17/6/2026 | The ACF to REST API plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.4. This is due to insufficient capability checks in the update_item_permissions_check() method, which only verifies that the current user has the edit_posts capability without checking… | |
| Aplazada | Alta (8.8) | 0.30% | — | Aa-team Premium AGE Verification / Restriction FOR WordpressAIAa-team Responsive Coming Soon Landing Page / Holding Page FOR WordpressAI | 6/1/2026 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in AA-Team Premium Age Verification / Restriction for WordPress, AA-Team Responsive Coming Soon Landing Page / Holding Page for WordPress allows Privilege Escalation.This issue affects Premium Age Verification / Restriction for WordPress: from n/a through 3.0.2; Responsive… | |
| Aplazada | Alta (8.6) | 0.27% | — | Rustaurius Five Star Restaurant ReservationsAI | 5/1/2026 | 7/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.4. | |
| Aplazada | Media (5.3) | 0.22% | — | Magnigenie RestropressAI | 31/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.7. | |
| Modificada | Alta (8.1) | 0.19% | — | Everestthemes Everest Backup | 31/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Path Traversal.This issue affects Everest Backup: from n/a through <= 2.3.11. | |
| Aplazada | Media (6.5) | 0.16% | — | Magnigenie RestropressAI | 30/12/2025 | 7/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magnigenie RestroPress restropress allows Stored XSS.This issue affects RestroPress: from n/a through <= 3.2.8.6. | |
| Aplazada | Media (5.4) | 0.24% | — | Kitforest Better Elementor AddonsAI | 30/12/2025 | 17/6/2026 | Missing Authorization vulnerability in wpdive Better Elementor Addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Better Elementor Addons: from n/a through 1.3.7. | |
| Aplazada | Media (5.4) | 0.12% | — | Rustaurius Five Star Restaurant ReservationsAI | 24/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Five Star Restaurant Reservations restaurant-reservations allows Cross Site Request Forgery.This issue affects Five Star Restaurant Reservations: from n/a through <= 2.7.8. | |
| Aplazada | Media (6.4) | 0.24% | — | Membership Plugin Restrict ContentAI | 23/12/2025 | 17/6/2026 | The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'register_form' and 'restrict' shortcodes in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Media (6.1) | 0.21% | — | Fivestarplugins Five Star Restaurant ReservationsAI | 21/12/2025 | 17/6/2026 | The Five Star Restaurant Reservations – WordPress Booking Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rtb-name' parameter in all versions up to, and including, 2.7.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.1) | 0.36% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not… | |
| Modificada | Alta (7.1) | 0.15% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Cross Site Request Forgery. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Modificada | Media (5.4) | 0.18% | — | Restajet Online Food Delivery System | 19/12/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Phishing, Forceful Browsing. This issue affects Online Food Delivery System: through 19122025. NOTE: The vendor was contacted early about this disclosure but did not respond in… | |
| Aplazada | Media (6.5) | 0.24% | — | Magnigenie RestropressAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Magnigenie RestroPress restropress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects RestroPress: from n/a through <= 3.2.3.5. | |
| Aplazada | Media (6.5) | 0.34% | — | Motopress Mp-restaurant-menuAI | 18/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Retrieve Embedded Sensitive Data.This issue affects Restaurant Menu by MotoPress: from n/a through <= 2.4.7. | |
| Aplazada | Media (4.3) | 0.22% | — | Codexpert INC Restrict Elementor WidgetsAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Codexpert, Inc Restrict Elementor Widgets, Columns and Sections restrict-elementor-widgets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict Elementor Widgets, Columns and Sections: from n/a through <= 1.12. | |
| Aplazada | Media (4.3) | 0.13% | — | Graham Quick Interest SliderAI | 16/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Graham Quick Interest Slider quick-interest-slider allows Cross Site Request Forgery.This issue affects Quick Interest Slider: from n/a through <= 3.1.5. | |
| Aplazada | Media (6.4) | 0.29% | — | Wpeverest User RegistrationAI | 15/12/2025 | 7/10/2026 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6 due to insufficient input sanitization… | |
| Aplazada | Media (5.8) | 0.39% | — | Kubernetes Kube-controller-managerAIPurestorage PortworxAI | 14/12/2025 | 17/6/2026 | A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback… |